VYPR

Parquet

by Apache

Source repositories

CVEs (2)

  • CVE-2026-73334HigSep 9, 2026
    risk 0.53cvss 8.1epss 0.00

    Potential problem for users of the org.apache.parquet.crypto.keytools package in Apache Parquet, versions 1.12 to 1.18. This package enables users to encrypt Parquet files via an envelope encryption mechanism that wraps (encrypts) data keys via a Key Management Service…

  • CVE-2025-46762HigMay 6, 2025
    risk 0.53cvss 8.1epss 0.01

    Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code. While 1.15.1 introduced a fix to restrict untrusted packages, the default setting of trusted packages still allows malicious classes from these…